cirmp AI · CIRMP compliance engine for SOCI Act 2018

For Australian critical infrastructure responsible entities

The board signs.
The pack signs itself.

Continuously assembled Critical Infrastructure Risk Management Program (CIRMP) packs for Australian critical infrastructure. Cited line by line. Signed by your CISO. Attested by your board.

New here? See the plain-English overview →

Illustrative pack · Energy entity

CIRMP attestation · Q3 FY26

Northern Water Authority
s.30AG annual attestation

p. 1 / 84

14 Mar 2026

4.2   Cyber and information security hazard

The responsible entity maintains a cyber security framework aligned to AESCSF[A]covering its operational technology estate. Identity controls enforce multi-factor authentication for users of the organisation's online services that hold sensitive data per Essential Eight Maturity Level 1[B], evidenced by Microsoft Entra exports dated 11 Mar 2026[C]. Patch cadence for internet-facing services remains within 48 hours (CrowdStrike Falcon, March cycle)[D].

4.2.1   Material risks identified

  • Legacy SCADA at Mt Crawford. Vendor support to Dec 2027. Compensating control: segregated VLAN, OT firewall ruleset frozen.
  • Third-party SIEM access reduced from 7 to 2 named operators following Mar 4 review.
SHA-256 · 9f3c…b14e● sealed

Sydney region

Rendering pinned to Sydney. Production planned for AWS Sydney

Reasoning trail

Every claim cites its source

Australian-owned

9t5 Pty Ltd team

Pre-release

Invite-only access

For SOCI Act 2018 responsible entitiesEnergy generationWater utilitiesFreight railPortsPublic hospitals (critical hospital asset class)Data centresFinancial market infrastructureDefence industryBroadcastingLiquid fuelsDNS operatorsGas distributionFor SOCI Act 2018 responsible entitiesEnergy generationWater utilitiesFreight railPortsPublic hospitals (critical hospital asset class)Data centresFinancial market infrastructureDefence industryBroadcastingLiquid fuelsDNS operatorsGas distribution

The annual scramble

The board attests every year. The evidence is still assembled by hand.

s.30AC of the SOCI Act requires responsible entities of the asset classes prescribed by the CIRMP Rules to adopt and maintain a written CIRMP. Thirteen of the twenty-two asset classes carry it. The four hazard domains come from ss.8 to 11 of the Rules. The responsible entity gives the annual report to its regulator within 90 days after the end of the financial year, and the board approves it first. Today that pack is scrambled together. Spreadsheets, SharePoint folders, vendor exports, a consultancy retainer. Where OT meets IT GRC is where audit defensibility goes to die. The Enhanced CIRMP Rules 2026 commenced on 10 June 2026. They reach nine of the thirteen classes. Grace periods hold every one of the new requirements back to 10 June 2027 or 10 June 2028.

13%

of the cyber security incidents ASD responded to in FY2024-25 involved critical infrastructure, out of more than 1,200. Up from 11 per cent in FY2023-24.

ASD Annual Cyber Threat Report 2024-25

22%

of Commonwealth entities reached Essential Eight Maturity Level 2 in 2025. Up from 15 per cent in 2024.

The Commonwealth Cyber Security Posture in 2025

How it works

Three steps. Same engine every quarter.

The pack is no longer a project. It is a continuously assembled artefact your CISO signs off and the board attests to.

How cirmp AI turns the tool exports you already produce into a board-signed CIRMP pack.

01

Bring in

The exports your security and IT tools already produce. Dragos, Claroty, Microsoft Sentinel, CrowdStrike Falcon, ServiceNow IRM, Workday. No agents to install.

Ingest · existing telemetry

02● the engine

Assemble

The engine is being built to draft the four-hazard report. Every line cites its source artefact. Reasoning trail viewable offline by the regulator. The new Enhanced Rules 2026 controls are evidenced inside the same four categories.

Continuous · four hazards

03

Sign

Your CISO reviews and signs. Board signs the s.30AG attestation. SHA-256 sealed. Cited offline-verifiable.

Attest · s.30AG

Tour the product

What you walk away with

What's in the pack.

One signed PDF. Four hazards. A reasoning trail your regulator can verify offline.

Four hazard domains. Cyber and information security. Personnel. Supply chain. Physical and natural.

Built to reflect the Enhanced CIRMP Rules 2026. The same four categories, with the new credential, access and network-segregation controls evidenced inside them.

● Illustrative · pre-release preview

Illustrative pack · Energy entity

CIRMP attestation · Q3 FY26

Northern Water Authority
s.30AG annual attestation

p. 1 / 84

14 Mar 2026

4.2   Cyber and information security hazard

The responsible entity maintains a cyber security framework aligned to AESCSF[A]covering its operational technology estate. Identity controls enforce multi-factor authentication for users of the organisation's online services that hold sensitive data per Essential Eight Maturity Level 1[B], evidenced by Microsoft Entra exports dated 11 Mar 2026[C]. Patch cadence for internet-facing services remains within 48 hours (CrowdStrike Falcon, March cycle)[D].

4.2.1   Material risks identified

  • Legacy SCADA at Mt Crawford. Vendor support to Dec 2027. Compensating control: segregated VLAN, OT firewall ruleset frozen.
  • Third-party SIEM access reduced from 7 to 2 named operators following Mar 4 review.
SHA-256 · 9f3c…b14e● sealed

Reasoning trail · 4 citations

A

AESCSF framework mapping

aescsf-v2-mapping.xlsx

IDM 02:14

B

Entra ID. MFA policy

entra-export-2026-03-11.json

IDM 02:21

C

Entra ID. Privileged users

priv-users-2026-03-11.csv

IDM 02:21

D

CrowdStrike Falcon. March cycle

falcon_posture_export_apr_2026.csv

IDM 02:28

offline-verifiableview all 271 →

Signed PDF

One pack the board attests to. SHA-256 sealed, time-stamped, offline-verifiable.

Four hazards

Cyber. Personnel. Supply chain. Physical and natural. Covered by default.

Reasoning trail

Every claim cites the control it answers and the rationale it was assessed on.

Sovereign

Being built to be AU-hosted and AU-owned.

Why you can trust the pack

Built to be checked, not taken on faith.

A compliance pack is only worth as much as your ability to defend it. We build the pack so a reviewer can trace every line back to where it came from.

Every claim carries a reasoning trail

Each control statement links back to the control it answers and the rationale it was assessed on. You can follow the working, not just read the conclusion.

People own the legal wording

The statutory attestation and penalty wording is fixed by people, not generated by the model. The board approves the pack and the entity signs it.

Assurance-ready by design

The pack is built so an independent reviewer can verify our working line by line. SHA-256 sealed and offline-verifiable, so the check does not depend on us.

§ 30AC / § 30AG obligations

Failing to give the board-approved s.30AG annual report is a civil penalty of 150 penalty units. Maintaining the CIRMP itself (s.30AC) carries 200. A false or misleading report is a separate criminal offence. The board signs it. The entity is liable.

SOCI Act 2018. s.30AG, civil penalty provisions.

s.30AG is the annual board-approved reporting requirement under the SOCI Act 2018, a 150 penalty unit civil penalty if it is not met. s.30AC is the obligation to maintain a written CIRMP, 200 penalty units. Knowingly giving false or misleading information is dealt with under the Criminal Code, not as a SOCI civil penalty.

The selection rule

Different entities need different frameworks. cirmp AI is being built to pick the right one.

CIRMP is the report. It does not tell you which cyber framework to use as the spine. The Rules name five accepted frameworks at s.8(4). The entity chooses one and meets its condition. We suggest a starting point by environment, then evidence against whichever one you choose.

Rule 01 · OT

For OT the usual starting points are AESCSF and NIST CSF. The entity chooses, not the sector.

Rule 02 · IT

For IT it's Essential Eight or AS ISO/IEC 27001. Often both.

Rule 03 · Hybrid

Most entities need an OT pillar and an IT pillar. Run in parallel.

Framework selector · by asset classPick the row that matches your environment.

Energy with OT

Electricity, gas, liquid fuels.

Framework →AESCSF, applicable profile by asset class

Non-energy with OT

Critical water, freight infrastructure, and freight services assets, plus the designated hospitals listed in Schedule 1 of the CIRMP Rules. Water and the two freight classes are in the enhanced nine, so they also meet the s.8A(3) table from 10 June 2028. Hospitals are not. IEC 62443 sits over the OT estate at the entity's option and is named in neither table.

Framework →NIST CSF at s.8(4). NIST CSF 2.0 at s.8A(3)

IT-dominant

Critical broadcasting, domain name system, data storage or processing, and financial market infrastructure assets. Broadcasting and domain name system are in the enhanced nine, so they also reach Essential Eight Maturity Level 2 or AS ISO/IEC 27001:2023 from 10 June 2028. Data storage or processing and financial market infrastructure carry the baseline CIRMP only.

Framework →Essential Eight ML1 or AS ISO/IEC 27001:2015

Hybrid estate

Most large CI entities.

Framework →Both pillars in parallel

Footnote ·CIRMP Rules (LIN 23/006), section 8(4) names five cyber security frameworks with the condition each one carries: AS ISO/IEC 27001:2015 with no condition, the Australian Signals Directorate (ASD) Essential Eight Maturity Model at Maturity Level 1, the Framework for Improving Critical Infrastructure Cybersecurity with no condition, the Cybersecurity Capability Maturity Model (C2M2) at Maturity Indicator Level 1, and the 2020-21 Australian Energy Sector Cyber Security Framework (AESCSF) Core at Security Profile 1. The entity chooses one and meets its condition. Since 10 June 2026 the Rules also carry a separate table at s.8A(3) for the nine enhanced asset classes: AS ISO/IEC 27001:2023, the Essential Eight at Maturity Level 2, NIST CSF 2.0, C2M2 version 2.1 at Maturity Indicator Level 2, and the 2023 AESCSF Framework Core at Security Profile 2. An entity in the nine satisfies both tables under s.4A(3), and s.8A(3) sits inside a grace period to 10 June 2028. Section 8A(4) permits an equivalent framework in place of items 2, 4 or 5.

Pricing

Continuous engagement.
Not a one-off audit.

Two parts. Implementation up front. Then four cycles a year, engine always on.

Talk to us about pricing

One-off · Implementation

Get cirmp AI live in your environment.

Secure-cloud deployment in your tenancy. Connector mapping for your existing OT and IT tooling. Asset-class customisation.

Ongoing · Quarterly

Four cycles a year. Engine always on.

Four CIRMP cycles a year, fully assembled and signed. Engine runs continuously between cycles.

The next cycle

Twenty minutes.
See it assemble itself.

See a sample CIRMP pack assembled live from real-world exports.

Book a walkthrough See the live demo